Details
-
Improvement
-
Status: Reviewable
-
Minor
-
Resolution: Unresolved
-
None
-
None
-
None
Description
The container launcher and the built-in executors are (at least partially) accessible to containerized user tasks. Since these processes may contain secrets or hold privileged resources, we can increase the difficulty of attacking them by preventing user tasks attaching to them with ptrace(2). This amounts to calling `prctl(PR_SET_DUMPABLE, 0)`.